Being Transparent is Merely the Beginning: Enforcing Purpose Limitation with Polynomial Approximation

Shuofeng Liu, Zihan Wang, Minhui Xue, Long Wang, Yuanchao Zhang, Guangdong Bai

Research output: Chapters, Conference Papers, Creative and Literary WorksRGC 32 - Refereed conference paper (with host publication)peer-review

2 Citations (Scopus)

Abstract

Obtaining the authorization of users (i.e., data owners) prior to data collection has become commonplace for online service providers (i.e., data processors), in light of the stringent data regulations around the world. However, it remains a challenge to uphold the principle of purpose limitation, which mandates that collected data should only be processed for the purpose that the data owner has originally authorized. In this work, we advocate algorithm specificity, as a means to enforce the purpose limitation principle. We propose ALGOSPEC, which obscures data to restrict its usability solely to an authorized algorithm or algorithm group. ALGOSPEC exploits the nature of polynomial approximation that given the input data and the highest order, any algorithm can be approximated with a unique polynomial. It converts the original authorized algorithm (or a part of it) into a polynomial and then creates a list of alternatives to the original data. To assess the efficacy and efficiency of ALGOSPEC, we apply it to the entropy method and Naive Bayes classification under datasets of different magnitudes from 102 to 106. ALGOSPEC significantly outperforms cryptographic solutions such as fully homomorphic encryption (FHE) in efficiency. On accuracy, it achieves a negligible Mean Squared Error (MSE) of 0.289 in the entropy method against computation over plaintext data, and identical accuracy (92.11%) and similar F1 score (87.67%) in the Naive Bayes classification.

© USENIX Security Symposium 2024.  All rights reserved.
Original languageEnglish
Title of host publicationSEC '24
Subtitle of host publicationProceedings of the 33rd USENIX Conference on Security Symposium
PublisherUSENIX Association
Pages6507-6524
Number of pages19
ISBN (Print)978-1-939133-44-1
Publication statusPublished - Aug 2024
Externally publishedYes
Event33rd USENIX Security Symposium (USENIX Security '24) - Philadelphia Marriott Downtown, Philadelphia, United States
Duration: 14 Aug 202416 Aug 2024
https://www.usenix.org/conference/usenixsecurity24

Publication series

NameProceedings of the 33rd USENIX Security Symposium

Conference

Conference33rd USENIX Security Symposium (USENIX Security '24)
PlaceUnited States
CityPhiladelphia
Period14/08/2416/08/24
Internet address

Fingerprint

Dive into the research topics of 'Being Transparent is Merely the Beginning: Enforcing Purpose Limitation with Polynomial Approximation'. Together they form a unique fingerprint.

Cite this